Platform  /  Governed pipeline  /  AI compliance
AI governance · Regulated enterprise

Disclosure enforced, never assumed.

Ship AI-assisted content at the speed your team needs without inheriting the compliance risk. Every asset declares how it was made before it can be approved; Article 50 disclosure clears only on a record with a separate declarer and approver; one rights verdict governs both what a reviewer sees and what the delivery doors release. All of it in the database, fail-closed by default.

The problem AI created

Speed is easy. Cleared-to-ship is the hard part.

AI shortens the edit, but 2026 disclosure rules turn labeling, likeness consent, and rights clearance into a procurement question. Speed only counts if the asset is cleared — and a policy document does not clear anything. WorkFreq turns the policy into an enforced gate on the path content actually travels.

EU AI Act Article 50

Disclosure is a gate, not a checkbox

An asset cannot be approved or delivered until it states how it was created, using a C2PA source type. Where that provenance is algorithmic, the database computes that a disclosure is owed and refuses the asset until an approved disclosure record exists. Article 50 binds from 2 August 2026.

ProvenanceDeclared, not inferred

Each asset carries one of five C2PA source types — from straight digital capture through to fully generated media. An upload that cannot say how it was made cannot reach approved or delivered.

SeparationDeclarer is not the approver

The disclosure table is insert-only. Approving writes a second record that supersedes the first rather than editing it, so the declaration cannot be rewritten after the fact and the chain reads as an audit trail. Approval authority is a grant with a grantor, a timestamp and a revoke path — not a role name.

Failure modeUnknown blocks

An asset whose provenance is undeclared is treated as blocked, not as clear, and an unresolved disclosure refuses delivery. The safe default is "do not ship," not "ship and hope."

Compliance is not legal advice; WorkFreq gives your team the enforced controls to operate the policy you set. Running a formal process? Send us the RFP →

The people in the frame

Consent recorded, presence witnessed

A consent is recorded next to a witnessed presence stamp — the moment that person was actually at the camera — in an append-only event plane written only by privileged database triggers, which tenants can read but never write. It deliberately outlives the rows it describes, so removing a roster entry does not erase the record that a consent existed. The consent document itself is not copied in: a digest is stored instead, proving which document was in force without putting a second copy of someone's name and signature beyond the reach of an erasure request. Biometric identification is not used — that is a standing ruling, not a default setting.

Rights & isolation

The other two gates at the delivery doors

Disclosure is one clause of a single rights verdict, not a check bolted on beside it. That one verdict weighs embargo, licence window, expiry, talent conflict and the Article 50 hold together, and the same function answers both the reviewer's screen and the delivery doors — so what a reviewer is told and what the door enforces cannot drift apart. Around it sits row-level tenant isolation, with cross-tenant access refused at the database rather than filtered in the application. See the full governed pipeline →

Roadmap

Governance first, automation second — never the other way around

This version ships no agentic capability as a customer-facing feature. Nothing here publishes, edits, or delivers content on its own. We say that plainly because a compliance platform that overstates its automation has already failed the review it is asking you to pass.

Agentic capability is on the roadmap, and it will arrive inside the plane that is already in production rather than beside it: the same required provenance declaration, the same Article 50 disclosure with its separate declarer and approver, the same one rights verdict at the delivery doors, and the same append-only record a tenant can read but not write. That ordering is the point — the governance exists first, so adopting agentic capability will be a decision a client makes, never a default it inherits. We are not putting a date on it, because a dated promise is a claim and an undated direction is a position.

Common questions

Before you ask

How do you handle EU AI Act Article 50 disclosure?

An asset must declare a C2PA source type before it can be approved or delivered. Where that provenance is algorithmic, the database computes that a disclosure is owed and clears it only on an approved record whose declarer and approver are separate entries. Fail-closed: unknown provenance blocks.

Do AI agents act on our content?

No. This version ships no agentic capability as a customer-facing feature — nothing publishes, edits, or delivers on its own. It is on the roadmap, and it will arrive governed by the compliance plane already in production.

Where are the rules enforced?

In the database, on the path content travels — not in app code that could be bypassed. One rights verdict answers both the reviewer's screen and the delivery doors, so display and enforcement cannot drift apart.

What is recorded about people in the content?

Consent plus a witnessed presence stamp, in an append-only plane that survives deletion of the rows it describes. The consent document is not copied in — a digest is, so erasure still reaches the original. Biometric identification is not used.